


Perceptive Security
SOC/SIEM Consultancy

Veeam Patches Critical RCE Vulnerability with CVSS 9.0 in Backup & Replication
Published:
7 January 2026 at 10:41:00
Alert date:
7 January 2026 at 13:02:49
Source:
thehackernews.com
Enterprise Applications, Zero-Day Vulnerabilities
Veeam has released security updates for its Backup & Replication software to address multiple vulnerabilities, including a critical remote code execution (RCE) flaw tracked as CVE-2025-59470 with a CVSS score of 9.0. The vulnerability allows a Backup or Tape Operator to perform remote code execution as the postgres user by sending malicious requests. This represents a significant security risk for organizations using Veeam's backup solutions.
Technical details
CVE-2025-59470 allows Backup or Tape Operator roles to perform remote code execution as the postgres user by sending malicious interval or order parameters. CVE-2025-55125 enables RCE as root through malicious backup configuration files. CVE-2025-59468 allows Backup Administrators to perform RCE as postgres user via malicious password parameters. CVE-2025-59469 permits file writing as root by Backup or Tape Operators. All vulnerabilities require privileged user roles within Veeam.
Mitigation steps:
Update to Veeam Backup & Replication version 13.0.1.1071 immediately. Follow Veeam's recommended Security Guidelines to reduce exploitation opportunities. Implement proper access controls for Backup Operator and Tape Operator roles as these are highly privileged positions.
Affected products:
Veeam Backup & Replication 13.0.1.180 and all earlier versions of 13 builds
Related links:
https://helpcenter.veeam.com/docs/vbr/userguide/configure_roles.html?ver=13
https://www.veeam.com/kb4792
https://helpcenter.veeam.com/docs/vbr/userguide/security_guidelines.html?ver=13
https://thehackernews.com/2024/07/new-ransomware-group-exploiting-veeam.html
https://thehackernews.com/2025/06/veeam-patches-cve-2025-23121-critical.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
